Skip to content

build(deps): bump org.springframework:spring-webmvc from 6.2.5 to 6.2.17 in /microservices-api-gateway/price-microservice#3450

Open
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/maven/microservices-api-gateway/price-microservice/org.springframework-spring-webmvc-6.2.17
Open

build(deps): bump org.springframework:spring-webmvc from 6.2.5 to 6.2.17 in /microservices-api-gateway/price-microservice#3450
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/maven/microservices-api-gateway/price-microservice/org.springframework-spring-webmvc-6.2.17

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Mar 20, 2026

Bumps org.springframework:spring-webmvc from 6.2.5 to 6.2.17.

Release notes

Sourced from org.springframework:spring-webmvc's releases.

v6.2.17

⭐ New Features

  • Leverage ResourceHandlerUtils in ScriptTemplateView #36459
  • Restore ScriptTemplateViewTests #36457
  • Fix log message in ConfigurationClassBeanDefinitionReader #36454
  • Resolve context initializers only once in AbstractTestContextBootstrapper #36431
  • Exclude legacy @javax.validation.Constraint from convention-based annotation attribute override check #36412
  • Optimize MediaType(MediaType, Charset) constructor #36351
  • Optimize the addition of a charset to the MediaType in AbstractHttpMessageConverter #36350
  • Consistent adaptation of HTTP headers on Servlet responses #36345
  • Improve performance of validation groups determination in WebFlux #36337
  • Detect all common size exceptions from Tomcat and Commons FileUpload 2.x #36324

🐞 Bug Fixes

  • Guard against invalid id/event values in Server Sent Events #36442
  • Incomplete debug message in ConfigurationClassBeanDefinitionReader #36411
  • Inconsistent ApplicationEventMulticaster state after removing ApplicationListener implemented by FactoryBean #36405
  • Graceful shutdown of SimpleAsyncTaskExecutor #36384
  • HttpMediaTypeException thrown when calculating compatible media types #36363
  • ResolvableType#getGenerics() breaks serialization #36347
  • Multipart upload leak on client abort (ByteBuf.release() not called) #36327

📔 Documentation

  • Document @Fallback alongside Primary in the reference manual and @Bean Javadoc #36441
  • Document registration recommendations for BeanPostProcessor and BeanFactoryPostProcessor #36436
  • Fix links to UriComponentsBuilder and polish examples #36406
  • Emphasize @Configuration classes over XML and Groovy in testing chapter #36394
  • Polish SpEL operator examples in reference docs #36375

🔨 Dependency Upgrades

  • Upgrade to JUnit 5.14.3 #36388
  • Upgrade to Micrometer 1.15.10 #36446
  • Upgrade to Reactor 2024.0.16 #36445

v6.2.16

⭐ New Features

  • Improve performance of hashcode calculations for request mappings #36297
  • Improve performance of HandlerMethod bean lookup #36296
  • Improve performance of validation groups determination #36295
  • Improve performance of single pattern request mappings #36294
  • Optimize NamedParameterUtils#buildValueArray by lazily fetching SqlParameter #36232
  • Consistently close streams through try-with-resources in FileCopyUtils #36224
  • SqlBinaryValue and SqlCharacterValue should support InputStream content with undetermined length #36220
  • DataBufferUtils.write() with NettyDataBuffer on JDK 25 hangs indefinitely #36189
  • WebClient (Reactor) attributes on Netty channel do not clear after connection release #36163

... (truncated)

Commits
  • 4e35a12 Release v6.2.17
  • 317a1f9 Leverage ResourceHandlerUtils in ScriptTemplateView
  • de6601f Restore ScriptTemplateViewTests
  • 47dc1c4 Fix log message in ConfigurationClassBeanDefinitionReader
  • d8c7793 Upgrade to SnakeYAML 2.6, Protobuf 4.34, H2 2.4.240
  • 99fbce1 Polishing (aligned with main)
  • d1e69a9 Upgrade to Reactor 2024.0.16 and Micrometer 1.15.10
  • 8dc888e Guard against invalid id/event values in Server Sent Events
  • 131f94f Use link for first reference to @⁠Fallback in @⁠Bean Javadoc
  • d4f4c69 Document @​Fallback alongside Primary in the reference docs and @​Bean Javadoc
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [org.springframework:spring-webmvc](https://github.com/spring-projects/spring-framework) from 6.2.5 to 6.2.17.
- [Release notes](https://github.com/spring-projects/spring-framework/releases)
- [Commits](spring-projects/spring-framework@v6.2.5...v6.2.17)

---
updated-dependencies:
- dependency-name: org.springframework:spring-webmvc
  dependency-version: 6.2.17
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Mar 20, 2026
@github-actions
Copy link

github-actions bot commented Mar 20, 2026

PR Summary

Bumps org.springframework:spring-webmvc from 6.2.5 to 6.2.17 in the price microservice. This update aligns the dependency with the latest release, including new features and bug fixes from v6.2.17 as described in the release notes.

Changes

File Summary
microservices-api-gateway/price-microservice/pom.xml Bumped dependency version of spring-webmvc from 6.2.5 to 6.2.17 in pom.xml.

autogenerated by presubmit.ai

Copy link

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

Review Summary

Commits Considered (1)
  • 1211631: build(deps): bump org.springframework:spring-webmvc

Bumps org.springframework:spring-webmvc from 6.2.5 to 6.2.17.


updated-dependencies:

  • dependency-name: org.springframework:spring-webmvc
    dependency-version: 6.2.17
    dependency-type: direct:production
    ...

Signed-off-by: dependabot[bot] support@github.com

Files Processed (1)
  • microservices-api-gateway/price-microservice/pom.xml (1 hunk)
Actionable Comments (0)
Skipped Comments (2)
  • microservices-api-gateway/price-microservice/pom.xml [41-41]

    best_practice: "Dependency version management: align with BOM/parent"

  • microservices-api-gateway/price-microservice/pom.xml [38-42]

    enhancement: "Direct dependency version bump: verify compatibility and alignment"

@sonarqubecloud
Copy link

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants